Vulnerabilities/

rsshub vulnerable to Cross-site Scripting via unvalidated URL parameters

Severity:
Medium

Description

When the URL parameters contain certain special characters, it returns an error page that does not properly handle XSS vulnerabilities, allowing for the execution of arbitrary JavaScript code.

Users who access the deliberately constructed URL are affected.

Recommendation

Update the rsshub package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
rsshub
Anything's wrong? Let us know Last updated on March 13, 2023

This issue is available in SmartScanner Professional

See Pricing